USN-8567-1: Linux kernel vulnerabilities

Publication date

20 July 2026

Overview

Several security issues were fixed in the Linux kernel.


Packages

  • linux - Linux kernel
  • linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems
  • linux-gcp-6.8 - Linux kernel for Google Cloud Platform (GCP) systems
  • linux-gke - Linux kernel for Google Container Engine (GKE) systems
  • linux-gkeop - Linux kernel for Google Container Engine (GKE) systems
  • linux-realtime - Linux kernel for Real-time systems
  • linux-realtime-6.8 - Linux kernel for Real-time systems

Details

It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (

It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • ARM64 architecture;
  • RISC-V architecture;
  • S390 architecture;
  • x86 architecture;
  • Block layer subsystem;
  • Cryptographic API;
  • Compute Acceleration Framework;
  • ACPI drivers;
  • Serial ATA and Parallel ATA drivers;
  • Drivers core;
  • Power management core;
  • DRBD Distributed Replicated Block Device drivers;
  • Rados block device (RBD) driver;
  • Compressed RAM block device driver;
  • Bluetooth drivers;
  • Bus devices;
  • Character device driver;
  • Clock framework and drivers;
  • Data acquisition framework and drivers;
  • Counter interface drivers;
  • CPU frequency scaling framework;
  • Hardware crypto device drivers;
  • CXL (Compute Express Link) drivers;
  • DMA engine subsystem;
  • EDAC drivers;
  • EFI core;
  • GPU drivers;
  • Greybus drivers;
  • HID subsystem;
  • Hardware monitoring drivers;
  • I2C subsystem;
  • IIO ADC drivers;
  • IIO subsystem;
  • InfiniBand drivers;
  • Input Device (Miscellaneous) drivers;
  • IRQ chip drivers;
  • LED subsystem;
  • Mailbox framework;
  • Multiple devices driver;
  • Media drivers;
  • MediaTek SMI driver;
  • NVIDIA Tegra memory controller driver;
  • Fastrpc Driver;
  • IBM Advanced System Management driver;
  • MMC subsystem;
  • MTD block device drivers;
  • Network drivers;
  • Ethernet bonding driver;
  • Mellanox network drivers;
  • Microsoft Azure Network Adapter (MANA) driver;
  • STMicroelectronics network drivers;
  • Ethernet team driver;
  • MediaTek network drivers;
  • Near Field Communication (NFC) drivers;
  • NTB driver;
  • NVDIMM (Non-Volatile Memory Device) drivers;
  • NVME drivers;
  • Device tree and open firmware driver;
  • PCI subsystem;
  • Pin controllers subsystem;
  • x86 platform drivers;
  • Broadcom BCM2835 power domain driver;
  • Generic PM domains;
  • i.MX PM domains;
  • Remote Processor subsystem;
  • S/390 drivers;
  • SCSI subsystem;
  • SLIMbus drivers;
  • Freescale SoC drivers;
  • Microchip PolarFire SoC system controller driver;
  • SPI subsystem;
  • Media staging drivers;
  • Realtek RTL8723BS SDIO drivers;
  • SM750 framebuffer staging driver;
  • TCM subsystem;
  • Thermal drivers;
  • TTY drivers;
  • UFS subsystem;
  • Cadence USB3 driver;
  • USB Device Class drivers;
  • ULPI bus;
  • USB core drivers;
  • DesignWare USB2 driver;
  • USB Gadget drivers;
  • USB Host Controller drivers;
  • Mustek MDC800 USB digital camera driver;
  • USB YUREX driver;
  • Renesas USBHS Controller drivers;
  • USB Type-C Connector System Software Interface driver;
  • VFIO drivers;
  • Framebuffer layer;
  • TSM TDX Guest driver;
  • Xen hypervisor drivers;
  • File systems infrastructure;
  • BTRFS file system;
  • Ceph distributed file system;
  • EROFS file system;
  • Ext4 file system;
  • F2FS file system;
  • FUSE (File system in Userspace);
  • GFS2 file system;
  • HFS+ file system;
  • Journaling layer for block devices (JBD2);
  • Network file systems library;
  • Network file system (NFS) server daemon;
  • NILFS2 file system;
  • File system notification infrastructure;
  • NTFS3 file system;
  • OCFS2 file system;
  • Diskquota system;
  • SMB network file system;
  • SquashFS file system;
  • Tracing file system;
  • UDF file system;
  • XFS file system;
  • Kernel CPU control infrastructure;
  • QorIQ DPAA2 FSL-MC bus driver;
  • Memory Management;
  • Integrity Measurement Architecture(IMA) framework;
  • KVM subsystem;
  • Memory management;
  • Networking core;
  • padata parallel execution mechanism;
  • PPP protocol drivers and compressors;
  • Linux Security Modules (LSM) Framework;
  • Tracing infrastructure;
  • Network traffic control;
  • Distributed Switch Architecture;
  • IPv4 networking;
  • IP tunnels definitions;
  • MAC80211 subsystem;
  • Netfilter;
  • User-space API (UAPI);
  • io_uring subsystem;
  • Audit subsystem;
  • BPF subsystem;
  • Control group (cgroup);
  • Perf events;
  • Kernel exit() syscall;
  • Kernel fork() syscall;
  • Kernel futex primitives;
  • KProbes tracing;
  • Locking primitives;
  • Kernel module support;
  • Padata parallel execution mechanism;
  • Cryptographic library;
  • Heterogeneous memory management;
  • KASAN memory debugging framework;
  • Asynchronous Transfer Mode (ATM) subsystem;
  • B.A.T.M.A.N. meshing protocol;
  • Bluetooth subsystem;
  • Ethernet bridge;
  • CAIF protocol;
  • CAN network layer;
  • Ceph Core library;
  • IPv6 networking;
  • XFRM subsystem;
  • L2TP protocol;
  • Management Component Transport Protocol (MCTP);
  • Multipath TCP;
  • NCSI (Network Controller Sideband Interface) driver;
  • NFC subsystem;
  • Open vSwitch;
  • Packet sockets;
  • Qualcomm IPC Router (QRTR);
  • RDS protocol;
  • RF switch subsystem;
  • Rose network layer;
  • RxRPC session sockets;
  • SCTP protocol;
  • SMC sockets;
  • Stream parser;
  • Sun RPC protocol;
  • TIPC protocol;
  • TLS protocol;
  • Unix domain sockets;
  • VMware vSockets driver;
  • Wireless networking;
  • X.25 network layer;
  • eXpress Data Path;
  • Landlock security;
  • ALSA framework;
  • Generic PCM loopback sound driver;
  • FireWire sound drivers;
  • HD-audio driver;
  • Creative Sound Blaster X-Fi driver;
  • AMD SoC Alsa drivers;
  • QCOM ASoC drivers;
  • Samsung ASoC drivers;
  • SoC audio core drivers;
  • SOF drivers;
  • STI ASoC drivers;
  • USB sound devices;
  • Objtool


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 LTS noble linux-image-6.8.0-1046-gkeop –  6.8.0-1046.50
linux-image-6.8.0-1059-gke –  6.8.0-1059.67
linux-image-6.8.0-1059-gke-64k –  6.8.0-1059.67
linux-image-6.8.0-1064-gcp –  6.8.0-1064.72
linux-image-6.8.0-1064-gcp-64k –  6.8.0-1064.72
linux-image-6.8.0-136-generic –  6.8.0-136.136
linux-image-6.8.0-136-generic-64k –  6.8.0-136.136
linux-image-6.8.1-1056-realtime –  6.8.1-1056.57  
linux-image-gcp-6.8 –  6.8.0-1064.72
linux-image-gcp-64k-6.8 –  6.8.0-1064.72
linux-image-gcp-64k-lts-24.04 –  6.8.0-1064.72
linux-image-gcp-lts-24.04 –  6.8.0-1064.72
linux-image-generic –  6.8.0-136.136
linux-image-generic-6.8 –  6.8.0-136.136
linux-image-generic-64k –  6.8.0-136.136
linux-image-generic-64k-6.8 –  6.8.0-136.136
linux-image-generic-lpae –  6.8.0-136.136
linux-image-gke –  6.8.0-1059.67
linux-image-gke-6.8 –  6.8.0-1059.67
linux-image-gke-64k –  6.8.0-1059.67
linux-image-gke-64k-6.8 –  6.8.0-1059.67
linux-image-gkeop –  6.8.0-1046.50
linux-image-gkeop-6.8 –  6.8.0-1046.50
linux-image-intel-iot-realtime –  6.8.1-1056.57  
linux-image-intel-iotg –  6.8.0-136.136
linux-image-kvm –  6.8.0-136.136
linux-image-laptop-23.10 –  6.8.0-136.136
linux-image-oem-20.04 –  6.8.0-136.136
linux-image-oem-20.04b –  6.8.0-136.136
linux-image-oem-20.04c –  6.8.0-136.136
linux-image-oem-20.04d –  6.8.0-136.136
linux-image-oem-22.04 –  6.8.0-136.136
linux-image-realtime –  6.8.1-1056.57  
linux-image-realtime-6.8.1 –  6.8.1-1056.57  
linux-image-virtual –  6.8.0-136.136
linux-image-virtual-6.8 –  6.8.0-136.136
22.04 LTS jammy linux-image-6.8.0-1064-gcp –  6.8.0-1064.72~22.04.1
linux-image-6.8.0-1064-gcp-64k –  6.8.0-1064.72~22.04.1
linux-image-6.8.1-1056-realtime –  6.8.1-1056.57~22.04.2  
linux-image-gcp –  6.8.0-1064.72~22.04.1
linux-image-gcp-6.8 –  6.8.0-1064.72~22.04.1
linux-image-gcp-64k –  6.8.0-1064.72~22.04.1
linux-image-gcp-64k-6.8 –  6.8.0-1064.72~22.04.1
linux-image-realtime-6.8.1 –  6.8.1-1056.57~22.04.2  
linux-image-realtime-hwe-22.04 –  6.8.1-1056.57~22.04.2  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

References



Have additional questions?

Talk to a member of the team ›